Skip to content

Add bastion session recording configuration and identity properties - #45630

Merged
santoshgh317 merged 16 commits into
Azure:release-microsoft-network-2026-01-01from
mwlee29:bastion-srconfig
Sep 4, 2026
Merged

santoshgh317 merged 16 commits into
Azure:release-microsoft-network-2026-01-01from
mwlee29:bastion-srconfig

Conversation

@mwlee29

Copy link
Copy Markdown
Member

ARM (Control Plane) API Specification Update Pull Request

Tip

Overwhelmed by all this guidance? See the Getting help section at the bottom of this PR description.

PR review workflow diagram

Please understand this diagram before proceeding. It explains how to get your PR approved & merged.

spec_pr_review_workflow_diagram

Purpose of this PR

What's the purpose of this PR? Check the specific option that applies. This is mandatory!

  • New resource provider.
  • New API version for an existing resource provider. (If API spec is not defined in TypeSpec, the PR should have been created in adherence to OpenAPI specs PR creation guidance).
  • Update existing version for a new feature. (This is applicable only when you are revising a private preview API version.)
  • Update existing version to fix OpenAPI spec quality issues in S360.
  • Convert existing OpenAPI spec to TypeSpec spec (do not combine this with implementing changes for a new API version).
  • Other, please clarify:
    • edit this with your clarification

Due diligence checklist

To merge this PR, you must go through the following checklist and confirm you understood
and followed the instructions by checking all the boxes:

  • I confirm this PR is modifying Azure Resource Manager (ARM) related specifications, and not data plane related specifications.
  • I have reviewed following Resource Provider guidelines, including
    ARM resource provider contract and
    REST guidelines (estimated time: 4 hours).
    I understand this is required before I can proceed to the diagram Step 2, "ARM API changes review", for this PR.
  • A release plan has been created. If not, please create one as it will help guide you through the REST API and SDK creation process.

Additional information

Viewing API changes

For convenient view of the API changes made by this PR, refer to the URLs provided in the table
in the Generated ApiView comment added to this PR. You can use ApiView to show API versions diff.

Suppressing failures

If one or multiple validation error/warning suppression(s) is detected in your PR, please follow the
suppressions guide to get approval.

Getting help

  • First, please carefully read through this PR description, from top to bottom. Please fill out the Purpose of this PR and Due diligence checklist.
  • If you don't have permissions to remove or add labels to the PR, request write access per aka.ms/azsdk/access#request-access-to-rest-api-or-sdk-repositories
  • To understand what you must do next to merge this PR, see the Next Steps to Merge comment. It will appear within few minutes of submitting this PR and will continue to be up-to-date with current PR state.
  • For guidance on fixing this PR CI check failures, see the hyperlinks provided in given failure
    and https://aka.ms/ci-fix.
  • For help with ARM review (PR workflow diagram Step 2), see https://aka.ms/azsdk/pr-arm-review.
  • If the PR CI checks appear to be stuck in queued state, please add a comment with contents /azp run.
    This should result in a new comment denoting a PR validation pipeline has started and the checks should be updated after few minutes.
  • If the help provided by the previous points is not enough, post to https://aka.ms/azsdk/support/specreview-channel and link to this PR.
  • For guidance on SDK breaking change review, refer to https://aka.ms/ci-fix.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 9 pipeline(s).
3 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Next Steps to Merge

✅ All automated merging requirements have been met! To get your PR merged, see aka.ms/azsdk/specreview/merge.

Comment generated by summarize-checks workflow run.

@github-actions github-actions Bot added ARMReview resource-manager TypeSpec Authored with TypeSpec WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 19, 2026
@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

API Change Check

APIView identified API level changes in this PR and created the following API reviews

Language API Review for Package
TypeSpec Microsoft.Network
Go sdk/resourcemanager/network/armnetwork
JavaScript @azure/arm-network
Java com.azure.resourcemanager:azure-resourcemanager-network
Python azure-mgmt-network

Comment generated by After APIView workflow run.

@github-actions

github-actions Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

TypeSpec suppressions requiring review (testing, non-blocking)

Status: ❌ Approval required (currently under testing, review NOT enforced) — 6 suppressions

⚠️ This check is currently in testing mode and is non-blocking — it will not prevent this PR from merging. This PR adds or updates the TypeSpec suppressions listed below. Suppressions are strongly discouraged — they bypass linter rules that protect API quality and consistency. Authors should avoid adding new suppressions and prefer fixing the underlying issue; reviewers should approve only when there is a clear, compelling justification and no reasonable alternative. Review each linked rule and source location, then apply Approved-TypeSpecSuppression only if every justification is acceptable. The Status column shows ✅ once the label is applied and ❌ while approval is pending.

New suppressions (2)

StatusRuleSourceJustification
❌@azure-tools/typespec-azure-resource-manager/lro-location-header
A 202 response should include a Location response header.
BastionHost.tsp#L77Rename of previous updateTags operation which uses a legacy async polling pattern
❌@azure-tools/typespec-azure-resource-manager/lro-location-header
A 202 response should include a Location response header.
BastionHost.tsp#L77Rename of previous updateTags operation which uses a legacy async polling pattern

Changed suppressions (4)

StatusRuleSourcePrevious justificationNew justification
❌@azure-tools/typespec-azure-resource-manager/secret-prop
RPC-v1-13: Check that property with names indicating sensitive information(e.g. contains auth, password, token, secret, etc.) are marked with Madara (@secret) decorator.
models.tsp#L11425FIXME: Update justification, follow aka.ms/tsp/conversion-fix for detailsPre-existing GA property; changing its schema (e.g. adding format: password / x-ms-secret) would be a breaking change. Whether GET/LIST returns this authorization key unmasked or masked is enforced at runtime by the backend based on the caller's privileges, not by the API schema, so Madara (@secret) is intentionally not applied. The dedicated listKeys POST action returns the unmasked key via the Madara (@secret) ExpressRouteAuthorizationKey response model.
❌@azure-tools/typespec-azure-resource-manager/secret-prop
RPC-v1-13: Check that property with names indicating sensitive information(e.g. contains auth, password, token, secret, etc.) are marked with Madara (@secret) decorator.
models.tsp#L12892FIXME: Update justification, follow aka.ms/tsp/conversion-fix for detailsPre-existing GA property; changing its schema (e.g. adding format: password / x-ms-secret) would be a breaking change. Whether GET/LIST returns this authorization key unmasked or masked is enforced at runtime by the backend based on the caller's privileges, not by the API schema, so Madara (@secret) is intentionally not applied. The dedicated listKeys POST action returns the unmasked key via the Madara (@secret) ExpressRouteAuthorizationKey response model.
❌@azure-tools/typespec-azure-resource-manager/secret-prop
RPC-v1-13: Check that property with names indicating sensitive information(e.g. contains auth, password, token, secret, etc.) are marked with Madara (@secret) decorator.
models.tsp#L11425FIXME: Update justification, follow aka.ms/tsp/conversion-fix for detailsPre-existing GA property; changing its schema (e.g. adding format: password / x-ms-secret) would be a breaking change. Whether GET/LIST returns this authorization key unmasked or masked is enforced at runtime by the backend based on the caller's privileges, not by the API schema, so Madara (@secret) is intentionally not applied. The dedicated listKeys POST action returns the unmasked key via the Madara (@secret) ExpressRouteAuthorizationKey response model.
❌@azure-tools/typespec-azure-resource-manager/secret-prop
RPC-v1-13: Check that property with names indicating sensitive information(e.g. contains auth, password, token, secret, etc.) are marked with Madara (@secret) decorator.
models.tsp#L12892FIXME: Update justification, follow aka.ms/tsp/conversion-fix for detailsPre-existing GA property; changing its schema (e.g. adding format: password / x-ms-secret) would be a breaking change. Whether GET/LIST returns this authorization key unmasked or masked is enforced at runtime by the backend based on the caller's privileges, not by the API schema, so Madara (@secret) is intentionally not applied. The dedicated listKeys POST action returns the unmasked key via the Madara (@secret) ExpressRouteAuthorizationKey response model.

For an overview of TypeSpec linting rules click here.
For a mapping from ARM lintdiff rules to corresponding TypeSpec linting rules click here.

💬 Have feedback on the TypeSpec suppression flow? Let us know.

@sandipsh Sandip Shahane (sandipsh) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (critic-verified, 2 iteration(s), converged) against commit 295dcf8. See inline comments for findings 1-5.

Approval labels observed: none.

@sandipsh Sandip Shahane (sandipsh) added ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 24, 2026
@github-actions github-actions Bot added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Aug 25, 2026
@mwlee29

Copy link
Copy Markdown
Member Author

This PR needs the Approved-Avocado tag to suppress the Swagger Avocado violation as the default tag intentionally includes vmssNetwork.json from 2018-10-01 for backward compatibility. Please find the reference PR where the suppression was provided: #41904

@mwlee29 Matthew Lee (mwlee29) added Approved-Avocado and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 25, 2026
@mwlee29 Matthew Lee (mwlee29) added WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required and removed ARMChangesRequested labels Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45630 at head SHA 4acc7b4007ced06372c884db1e59410a6d88d75f | Triggered by: manual/scheduled ARM review run

Approval labels observed: BreakingChange-Go-Sdk-Approved, BreakingChange-JavaScript-Sdk-Approved, BreakingChange-Python-Sdk-Approved, Approved-Avocado.

Category Count
🔴 Blocking 0
🟠 Warning 1
🔵 Suggestion 0

Reconciliation note: Five prior findings from earlier runs (anonymous PATCH body, unconstrained armResourceIdentifier on userAssignedIdentityId, two example resource-ID inconsistencies, and the BastionHosts_UpdateTags→BastionHosts_Update operationId rename) were previously resolved as fixed by commits between 2026-08-24 and 2026-08-27. Commit f03cacf ("Revert previous changes which maintained the old operation") reintroduced the operation-ID rename: stable/2026-01-01/virtualNetwork.json's PATCH operation is again BastionHosts_Update (previously restored to BastionHosts_UpdateTags in 8be842a), with its request body now BastionHostUpdate instead of TagsObject. A reply was posted on the existing resolved thread rather than a new duplicate finding, per reconciliation rules. It is scored Warning (not Blocking) because SDK-language breaking-change approvals are present, though no ARM-review-specific BreakingChange-Approved-* label was observed.

Critic availability: The arm-api-review-critic-runtime subagent reported that its required protocol/input-template files were not resolvable in this run, so it returned a failed dispatch rather than a verdict. Per protocol, this run proceeds with critic: unknown and does not treat any finding as Critic-verified. No other Blocking or Warning candidates were identified in this pass across the TypeSpec, common.json, and virtualNetwork.json changes (identity/sessionRecordingConfiguration placement, common-types ManagedServiceIdentity $ref usage, x-ms-enum/modelAsString on SessionRecordingIdentityType, and arm-id format with x-ms-arm-id-details on userAssignedIdentityId all look correct).

The operationId rename is the key open item for the author to resolve or get approved before merge.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: existing | critic: unknown | head-sha: 4acc7b4

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (Critic unavailable; reviewer self-check only, 1 iteration, reintroduced regression flagged) against commit 4acc7b4007ced06372c884db1e59410a6d88d75f. All findings are reported in the summary comment and as a reply to the existing thread; no new inline comments were queued this run.

Approval labels observed: BreakingChange-Go-Sdk-Approved, BreakingChange-JavaScript-Sdk-Approved, BreakingChange-Python-Sdk-Approved, Approved-Avocado.

🔍 ARM API review by ARM API Review: Automated Workflow

@gary-x-li

Copy link
Copy Markdown
Contributor

Suppression review result: not approved as currently justified. The suppression report at #45630 (comment) identifies the new lro-location-header suppression but does not approve it. This supersedes the non-blocking characterization in #45630 (comment) and #45630 (review).
In stable 2026-01-01, BastionHosts_Update is an asynchronous PATCH whose 202 response has Azure-AsyncOperation and Retry-After but no required Location header. Copying the older updateTags pattern is not a technical justification for the new GA suppression.
Please add the required Location header and remove the suppression after verifying LroLocationHeader no longer fires. If a technical constraint prevents that, document the constraint and operational impact here for ARM API peer review.
Approval context: No Approved-TypeSpecSuppression label was observed at the session SHA. Please confirm whether approval already covers this specific suppression. If it does, ensure the label is applied and resolve this conversation; otherwise add the required Location header and remove the suppression, or obtain approval for a documented technical exception.

The new update operation is effectively the same as the updateTags operation with a different body. It uses some legacy polling pattern

The missing Location header is blocking. The ARM RPC asynchronous PATCH contract requires a 202 response to include both Location and Azure-AsyncOperation headers.

The operation-ID change is acceptable. It does not affect the HTTP method, URI, or service behavior; it only influences generated SDK naming and tooling. Since 2026-01-01 is not yet published on main, no released same-version contract is being changed, and the relevant SDK compatibility checks and approvals cover the future generated surface.

@gary-x-li Gary Li (gary-x-li) added ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Sep 1, 2026
@mwlee29

Copy link
Copy Markdown
Member Author

Gary Li (@gary-x-li) Currently our PATCH path doesn't return a Location header in the response and has never done so. This is a pre-existing issue that was previously suppressed and has nothing to do with my changes. The reason it's surfaced now is because I'm renaming the operation to something more appropriate (updateTags -> update). With this context, is the missing Location header still blocking?

@gary-x-li

Copy link
Copy Markdown
Contributor

Gary Li (Gary Li (@gary-x-li)) Currently our PATCH path doesn't return a Location header in the response and has never done so. This is a pre-existing issue that was previously suppressed and has nothing to do with my changes. The reason it's surfaced now is because I'm renaming the operation to something more appropriate (updateTags -> update). With this context, is the missing Location header still blocking?

Given this is a pre-existing issue, and likely won't break at runtime (most client tools use Location header first, then falls back to Azure-AsyncOperation header), I won't block this PR.

Can you please create a work item to track this work, and paste the link here?

@mwlee29

Copy link
Copy Markdown
Member Author

Gary Li (Gary Li (Gary Li (@gary-x-li))) Currently our PATCH path doesn't return a Location header in the response and has never done so. This is a pre-existing issue that was previously suppressed and has nothing to do with my changes. The reason it's surfaced now is because I'm renaming the operation to something more appropriate (updateTags -> update). With this context, is the missing Location header still blocking?

Given this is a pre-existing issue, and likely won't break at runtime (most client tools use Location header first, then falls back to Azure-AsyncOperation header), I won't block this PR.

Can you please create a work item to track this work, and paste the link here?

https://msazure.visualstudio.com/One/_workitems/edit/39551597

@mwlee29 Matthew Lee (mwlee29) added WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required and removed ARMChangesRequested labels Sep 3, 2026
@github-actions github-actions Bot added WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Sep 3, 2026
@gary-x-li Gary Li (gary-x-li) added ARMSignedOff <valid label in PR review process>add this label when ARM approve updates after review Approved-Suppression and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45630 at head SHA 4acc7b4007ced06372c884db1e59410a6d88d75f | Triggered by: pull_request_target

Approval labels observed: BreakingChange-Go-Sdk-Approved, BreakingChange-JavaScript-Sdk-Approved, BreakingChange-Python-Sdk-Approved, Approved-Suppression.

Category Count
🔴 Blocking 0
🟠 Warning 0
🔵 Suggestion 0

No new commits since the last automated review at this same head SHA (4acc7b4007ced06372c884db1e59410a6d88d75f, run 33539479667). Reconciliation against all three discussion surfaces (inline review threads, top-level comments, and reviews) found no state change: five prior findings (anonymous PATCH body, unconstrained userAssignedIdentityId, two example resource-ID/name mismatches, and a public-IP resource-ID typo) remain fixed and resolved (SKIP-COVERED), and one previously-flagged, still-open issue remains unresolved — the PATCH operationId rename from BastionHosts_UpdateTags to BastionHosts_Update on stable/2026-01-01/virtualNetwork.json (introduced via @renamedFrom(Versions.v2026_01_01, "updateTags") in BastionHost.tsp line 81), most recently reintroduced by commit f03cacf after being fixed in 8be842a1. No matching BreakingChange-Approved-* label is observed at this session SHA (only SDK-language approvals BreakingChange-Go-Sdk-Approved/BreakingChange-JavaScript-Sdk-Approved/BreakingChange-Python-Sdk-Approved are present, which do not count as ARM API-review breaking-change approval). This is already flagged on the existing inline thread (#45630 (comment)); it is not reposted here per reconciliation rules, and no new commits changed its state, so no new resolution action was taken either.

Critic availability: The arm-api-review-critic-runtime subagent reported that its required protocol/template files could not be loaded in this environment, so it returned a failed dispatch rather than a verdict. Per protocol this run proceeds with critic: unknown, no finding is treated as Critic-verified, and no Blocking finding is posted or newly escalated this run.

No new findings were identified in this run across the TypeSpec (BastionHost.tsp, models.tsp), common.json (SessionRecordingIdentityType), and virtualNetwork.json (BastionHostUpdate, BastionSessionRecordingConfiguration, SessionRecordingIdentity, top-level identity on BastionHost) changes. No label changes were made (no new Blocking finding was queued for publication this run).

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: existing | critic: unknown | head-sha: 4acc7b4

🔍 ARM API review by ARM API Review: Automated Workflow

@mwlee29

Copy link
Copy Markdown
Member Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
You have several pipelines (over 10) configured to build pull requests in this repository. Specify which pipelines you would like to run by using /azp run [pipelines] command. You can specify multiple pipelines using a comma separated list.

@santoshgh317
santoshgh317 self-requested a review September 4, 2026 05:48
@santoshgh317
santoshgh317 merged commit e6b84bb into Azure:release-microsoft-network-2026-01-01 Sep 4, 2026
260 of 265 checks passed
@santoshgh317 santoshgh317 mentioned this pull request Sep 4, 2026
5 of 9 tasks
santoshgh317 added a commit that referenced this pull request Sep 15, 2026
* Add API version 2026-01-01 for Microsoft.Network (#45569)

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>

* Add Enum values for VPN migrationType (#45647)

Co-authored-by: Akshat Kale <akale@microsoft.com>

* Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3

* [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625)

* Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01

Ports the change from azure-rest-api-specs-pr PR 29807 onto the public
2026-01-01 release branch.

Adds three read-only properties that NRP surfaces from api-version
2026-01-01 for Application Gateway WAF:

- paranoiaLevel on ApplicationGatewayFirewallRule
- displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat
- displayName on ApplicationGatewayFirewallManifestRuleSet
- displayName on DefaultRuleSetPropertyFormat

paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel
with values PL1 to PL4.

All new members are annotated with @added(Versions.v2026_01_01). The change is
additive and all new properties are optional.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Retrigger CI

The SDK Validation - Rust build failed on a transient GitHub timeout
while installing the Azure SDK Tools CLI. Nothing in the spec changed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766)

* Add Centurion WAF updates for 2026-01-01

Update WAF policy tier and reserved capacity support.

Add Basic_v2 and Basic_WAF_v2 SKUs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic v2 application gateway tiers

WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic WAF and application gateway examples

Add Basic WAF policy create/get examples and Basic-tier coverage.

Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764)

* Add AuthenticationPolicy support for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align AuthenticationPolicy contract with service behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Enforce AuthenticationPolicy name and binding constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

---------

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650)

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01

Adds optional min/max allocation-size bounds to the Microsoft.Network
IpamPool resource in api-version 2026-01-01:

- IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize
- IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize
  marked x-nullable so an explicit null clears the bound while an absent
  bound is preserved, per ARM merge-patch semantics.

Both properties are gated with @added(Versions.v2026_01_01) so earlier
api-versions are unchanged. Regenerated virtualNetwork.json and updated
the 2026-01-01 IpamPools Create/Get/List/Update examples.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Move min/max allocation size into dedicated IpamPool examples

The allocation-size bounds are optional, so the baseline IpamPools
examples should not imply they are always supplied. Restores
IpamPools_Create/Get/List/Update to their original content and adds
dedicated examples that exercise the feature:

- IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds.
- IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds.
- IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both
  bounds with an explicit null, per ARM merge-patch semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address ARM review: drop nullable union on new min/max update properties

New properties must not use a nullable union, since backward
compatibility does not apply to additions. The RP already treats an
empty string as a clear on PATCH, so the explicit null is unnecessary.

- IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string,
  removing the no-nullable suppressions and x-nullable from the swagger.
- Document clearing via an empty string.
- IpamPools_UpdateClearAllocationBounds example now clears with "".

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface

Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default
tag intentionally retains stable/2018-10-01/vmssNetwork.json for
backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix Avocado suppression tool name to SwaggerAvocado

Per ARM reviewer bot feedback on PR #45650: the suppression tool name
has no space.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add approvalReference to private endpoint connection in 2026-01-01 (#45604)

* Add approvalReference (create-only) to private endpoint connection in 2026-01-01

Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Regenerate vmssNetwork.json for approvalReference (Vmss project)

The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Remove x-ms-mutability (create-only) from approvalReference

Per internal discussion, drop the create-only mutability restriction on
approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create)
decorator in Common/main.tsp and regenerates the Network and Vmss project
swaggers so x-ms-mutability is no longer emitted. The approvalReference
property and ApprovalReference model are retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Type approvalReference.privateEndpointId as armResourceIdentifier

Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources.

---------

Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Add ExpressRoutCircuit on ExpressRouteLag (#45689)

* Add ExpressRoutCircuit on ExpressRouteLag

* Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY)

Fix response bodies to match request: LAG reference lagName (was test),
enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844)

* Add advanced routing features to Application Gateway for API version 2026-01-01

* buid artifacts after changes to models.tsp

* added examples

* fix merge conflict

---------

Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>

* Modify sdk-suppressions.yaml for breaking changes (#45914)

Updated breaking changes for Azure SDK suppressions in network resource manager.

* [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905)

* Add ExpressRoute circuit migration APIs

Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression.

* Fix Network specification validation

Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package.

* Fix Network Avocado suppression

Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme.

* Fix Network validation suppressions

* Correct Avocado suppression identifier

* Geo-Ip filter changes (#45631)

* Geo Ip Filter Changes

* Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model

* Fixing Swagger ModelValidation Filure related errors

* Dummy Push to reinitate build

* Type Spec validation failure fix

* Remove duplicate GeoIP filter properties

---------

Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>

* Add NeuroShield API for 2026-01-01 (#45722)

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Align NeuroShield contract with service behavior

Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Refine NeuroShield 2026-01-01 contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield validation regressions

* Address ARM review feedback for NeuroShield

Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield LintDiff suppressions

* Use standard ARM entity tag property

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679)

* Added post calls for expressroute auth key

* Added the objects in 2026-01-01 version

* addressed ai comments

* Addressed comments

* fixed

* removed suppression

* fixed suppressions

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>

* Fix Hub virtual network IPv6 peering contract (#45637)

* Fix IPv6 peering contract for Network 2026-01-01
* Correct IPv6 peering contract in Network 2025-09-01
* Update client.tsp

* Update sdk-suppressions.yaml

---------

Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com>

* Correct AuthenticationPolicy contract for 2026-01-01 (#45892)

* Correct authentication policy contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Keep provider type extensible

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Document authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align authentication examples with service

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Restore authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags

The tags-only PATCH takes the shared Network RP TagsObject body, matching
ApplicationGateways_UpdateTags. The service only updates tags on this
operation, so identity does not belong in the request body.

* Complete authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Correct Basic v2 authentication example

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Address ARM review feedback on AuthenticationPolicy 2026-01-01

- Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope.
- Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation.
- Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret.
- Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Also scope PatchIdentityProperty suppression to the PATCH body parameter path

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove AuthenticationPolicy PATCH operation

The service supports only GET, PUT, and DELETE for authenticationPolicies,
matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships
without a PATCH. Removing the tags-only PATCH also resolves the
PatchIdentityProperty finding at its source: that rule fires only on an
existing PATCH, so with no PATCH the identity envelope property no longer
needs a suppression.

- Remove AuthenticationPolicies_UpdateTags and its source and generated examples.
- Drop the PatchIdentityProperty suppression.
- Restore the TrackedResourcePatchOperation no-PATCH suppression.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression

The AuthenticationPolicy PATCH operation was removed, so the patch response
entry in the where: list no longer matches anything.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Restore AuthenticationPolicy PATCH with a resource-specific update model

AuthenticationPolicy is a tracked resource: it extends the Network RP
Resource base type, which supplies location, tags and x-ms-azure-resource.
ARM requires resource providers to support PATCH for updating tags on a
tracked resource, so removing the operation was incorrect.

Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters
model carrying both tags and identity, rather than the shared TagsObject.
This satisfies the tracked-resource tags requirement and the MSI onboarding
requirement that the control plane accept identity updates on PATCH, which
means PatchIdentityProperty is now satisfied at the source and needs no
suppression.

- Add AuthenticationPolicyUpdateParameters (tags, identity).
- Add AuthenticationPolicies_Update, replacing the former tags-only
  AuthenticationPolicies_UpdateTags.
- Add an example exercising both tags and identity updates.
- Drop the TrackedResourcePatchOperation suppression, no longer applicable.
- Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add bastion session recording configuration and identity properties (#45630)

* Add bastion session recording configuration property

* Fix the patch body for identity support

* Update examples

* Fix prettier violation

* Revert documentation changes

* Add BastionHostUpdate model instead of anonymous type

* Add tpye constraint for userAssignedIdentityId

* Fix invalid arm id for public ip in example

* Fix wrong name in 200 responses in new examples

* Fix documentation for BastionHostUpdate

* Preserve existing updateTags operation

* Update suppression justification

* Revert previous changes which maintained the old operation

* Update suppression justification for update operation

---------

Co-authored-by: Matthew Lee <matthelee@microsoft.com>

* Add azureFirewall enableAiAddOn (#45976)

* Add azureFirewall enableAiAddOn

* Enable aiSecurityAddOn in Azure Firewall configuration

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* copilot messed up, fix typescript

* fix fields in exampels

* fix fields in examples

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208)

This reverts commit efb6f29.

* Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260)

* Address swagger review findings on AuthenticationPolicy

Resolves five of the review findings at the source rather than by
suppression, removing four AuthenticationPolicy suppressions.

RequiredReadOnlySystemData: declare systemData explicitly on
AuthenticationPolicy, following the existing Network RP pattern used by
AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only.

RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the
sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only
resource in this project overriding the delete response; every sibling
uses the default. Removes the DeleteResponseCodes and
DeleteOperationResponses suppressions.

SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only
fires on properties typed as the builtin string, and clientSecret is
typed url, so the suppression had no effect. The property holds only a
Key Vault reference, which the documentation now states explicitly. The
XMSSecretInResponse suppression is also removed, as nothing in the
generated file is marked x-ms-secret.

RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to
$.definitions.AuthenticationPolicy, and explain why
LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types
version is pinned package-wide by arm-types-dir, so the finding applies
to every common-types reference in the file rather than to any single
definition.

Section 4.1: document the authenticationPolicy Features member instead of
suppressing documentation-required, and replace the placeholder FIXME
justification on WebApplicationFirewallPolicyTier with a real one.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01

Three CI failures introduced by the previous review-feedback commit:

1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added
   for this rule only covered $.definitions.AuthenticationPolicy, but the rule
   also fires on AuthenticationPolicyListResult. Added that definition to the
   scope and extended the reason to explain that the list result is a paged
   envelope rather than a resource.

2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec
   secret-prop suppression did not clear this because the swagger rule matches
   purely on the property name ending in a sensitive keyword. The property only
   ever carries an absolute HTTPS Key Vault reference URL, never secret
   material, so annotating it with x-ms-secret would be incorrect - it would
   stop the service returning the reference in GET. Renamed the property to
   clientSecretUrl, which both clears the rule without any suppression and
   describes the value accurately. 2026-01-01 is not yet published, so the
   rename carries no breaking-change cost.

3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation
   now declares a 200 response, so AuthenticationPolicyDelete.json needs a
   matching (bodyless) 200 entry alongside the existing 204.

Swagger Avocado remains failing with MULTIPLE_API_VERSION on the
package-2026-01-01 tag. That failure reproduces on the base release branch PR
(#46086) and is unrelated to this change.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Rename clientSecretUrl to clientSecretUri

TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces
@azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties
ending in 'Url' must use the 'Uri' suffix so the generated C# surface is
idiomatic. The local emit-only compile of the Network project does not run
client.tsp, so this was missed.

clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match,
which only fires on names ending in a sensitive keyword.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Revert clientSecret rename and suppress XMSSecretInResponse instead

The rename to clientSecretUrl/clientSecretUri was wrong. The property name is
part of the contract already implemented by the Network resource provider, so
the spec has to match NRP rather than pick a name that happens to dodge the
linter's keyword match. Reverted to clientSecret.

To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to
$.definitions.AuthenticationProviderProperties.properties.clientSecret. The
justification is substantive rather than a waiver: the property carries only an
absolute HTTPS Key Vault secret URL, never secret material - the secret value is
read from Key Vault at runtime using the resource's user-assigned identity and
is never accepted or returned by this API. Annotating it with x-ms-secret would
be actively incorrect, because that would stop the service returning the Key
Vault reference on GET, which callers need in order to see how a policy is
configured.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>
Co-authored-by: Akshat Kale <kaleakshat@gmail.com>
Co-authored-by: Akshat Kale <akale@microsoft.com>
Co-authored-by: yaarark <yaararonenkr@gmail.com>
Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com>
Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com>
Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com>
Co-authored-by: ajoyduwary <ajoyduwary@gmail.com>
Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com>
Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com>
Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>
Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com>
Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com>
Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>
Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com>
Co-authored-by: carenlim20 <carenlim+github@microsoft.com>
Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Matthew Lee <mwlee29@gmail.com>
Co-authored-by: Matthew Lee <matthelee@microsoft.com>
Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants